Data Processing Agreement
Last updated: 03 August 2026
Data Processing Agreement (DPA)
GDPR Art. 28 requires this agreement.
1. Parties and Subject Matter
PallasMark is a software service operated by RecRam Inc. ("Company"), a company incorporated in the State of Delaware, United States. RecRam Inc. is wholly owned by RecRam Yazılım Anonim Şirketi, headquartered in Kocaeli, Turkey, which serves as the group's head office and operational base.
- RecRam Inc. (USA) — 112 Capitol Trail Suite A1127, Newark, Delaware 19711, United States · EIN: 38-4300256 · Registered Agent: Social Enterprise LLC
- RecRam Yazılım Anonim Şirketi (Turkey, headquarters and parent) — Muallimköy Mah. Deniz Cad. Muallimköy T.G.B. 1.Etap 1.1.C1 Blok No:143/8 İç Kapı No:1, Gebze/Kocaeli · Tax office: Uluçınar Vergi Dairesi · Tax no: 7342530245 · Trade registry no: 40113 · MERSİS no: 0734253024500001
- Contact (single address for all legal, privacy, and KVKK requests): hello@pallasmark.com
RecRam Yazılım Anonim Şirketi acts as RecRam Inc.'s Turkey-based data controller representative under KVKK Art. 6698 and Art. 11 of the Regulation on the Data Controllers' Registry.
This DPA is entered into between the Company identified above ("Data Processor / PallasMark") and the registered merchant ("Data Controller / Merchant"), pursuant to GDPR Art. 28 and KVKK Art. 12.
This DPA governs the processing of the Merchant's buyers' personal data in connection with PallasMark's services.
2. Scope of Processing
Categories of personal data processed:
- Contact data: buyer email address or phone number
- Delivery proof files: video and photo recordings
- Electronic approval record: IP address, device/browser fingerprint, timestamp, hash of the accepted text
- Session recording: on-page interaction replay (retained for 180 days)
- Optional: geolocation coordinates
Purpose: Create delivery evidence, record buyer approvals, and retain those records on behalf of the Merchant.
Duration: Term of the Terms of Service, plus the 30-day export window granted to the Merchant after termination.
3. Obligations of the Processor (PallasMark)
- Process personal data only on the Merchant's documented instructions (GDPR Art. 28(3)(a))
- Ensure personnel with data access are bound by confidentiality obligations (GDPR Art. 28(3)(b))
- Implement appropriate technical and organisational security measures (GDPR Art. 32)
- Not engage another processor without the Merchant's prior consent (GDPR Art. 28(3)(d))
- Assist the Merchant in responding to data subject rights requests (GDPR Art. 28(3)(e))
- Notify the Merchant within 72 hours of becoming aware of a personal data breach (GDPR Art. 33)
- Return or destroy all personal data upon termination (GDPR Art. 28(3)(g))
4. Obligations of the Controller (Merchant)
- Ensure a valid legal basis for processing buyers' personal data
- Inform buyers of delivery evidence recording under KVKK Art. 10 / GDPR Art. 13
- Ensure that processing instructions comply with GDPR and KVKK
- Configure the approval-page consent text (consent_text) in consultation with its own legal counsel — this text is Merchant-configurable
5. Sub-processors
PallasMark uses the following approved sub-processors:
- Cloudflare, Inc. — storage of video/photo evidence files (object storage, global content delivery network)
- Resend and EmailIt — sending email notifications
- Twilio Inc. — sending SMS notifications
- Meta Platforms, Inc. (WhatsApp Business Platform) — sending WhatsApp notifications
- Paddle.com Market Ltd. and/or Stripe, Inc. — payment processing (Merchant's chosen provider; card data is held by these providers and never reaches us)
- netcup GmbH (Germany) — infrastructure provider hosting the application server and database
Merchants will be notified 14 days before a new sub-processor is engaged. All sub-processors are bound by equivalent data protection obligations (GDPR Art. 28(2)-(4)).
6. International Data Transfers
Our application server and database are hosted in Germany (EU). Transfers outside the EEA (e.g., to Cloudflare, Twilio, Meta, and RecRam Inc. in the USA) are made under EU Standard Contractual Clauses (SCCs, Commission Decision 2021/914). In Turkey, transfers to countries with a KVKK Art. 9 adequacy decision are permitted freely; others require explicit consent or a Board decision.
7. Security Measures
- TLS 1.2+ encryption in transit, AES-256 at rest
- SHA-256 hash-based file integrity verification
- Role-based access control and signed (Ed25519) audit logs
8. Post-Termination Data Management
Upon termination: the Merchant may export data within 30 days; after that PallasMark deletes all personal data (including backups); deletion is confirmed via an audit record.
9. Applicable Law
This document is subject to two separate legal regimes: (a) for Merchants domiciled or registered within the Republic of Turkey, Turkish law applies and the courts and enforcement offices of Istanbul (Merkez) have exclusive jurisdiction. (b) for Merchants domiciled outside Turkey, the law of the State of Delaware, USA applies and the courts of Delaware (or the applicable federal courts) have jurisdiction. In both cases, mandatory statutory rights of consumers and EU/EEA users remain unaffected.
Revision History
- 03 Aug 2026v2.2Initial version — prepared with real company details (tokenized).